openocd

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/openocd_run.py

This module is primarily a CLI wrapper around OpenOCD for legitimate device programming/management, but it introduces a significant semantic command-execution risk by supporting action='raw' and forwarding user-provided --command strings directly into OpenOCD as '-c' commands when allowed by configuration. It also passes attacker-influenced cfg/search selections to OpenOCD via '-f'/'-s'. While there are no clear malware/exfiltration indicators in this fragment, the security risk is elevated for scenarios where an attacker can control CLI arguments or configuration inputs (impacting hardware integrity and enabling unintended OpenOCD behavior).

Confidence: 67%Severity: 52%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:15 AM
Package URL
pkg:socket/skills-sh/zhinkgit%2Fembeddedskills%2Fopenocd%2F@a4d4060834c91fd2b68dcc5eec13f1863b3971e1d5042cf1852651cf5f156a6f
Security Audit — socket — openocd